Evaluating Cyber-Threat Awareness and Human Vulnerability Across the Public Sector and Civil Society
Abstract
Effective cybersecurity focuses less on overall risk averages and more on identifying an organization'smost vulnerable links. Assessing individual user behavior and susceptibility provides a criticalbenchmark for security policies and training programs. Managing human-centric risk has become justas vital to organizational health as maintaining IT infrastructure and responding to immediate cyberthreatsEven with extensive training, formal policies, and technical audits, managing human cybersecurityawareness remains a critical vulnerability. Most employees struggle to recognize day-to-day threats,making them susceptible to social engineering attacks and inclined to bypass security controls tomaximize productivity. Consequently, security awareness remains largely reactive, with usersprioritizing policy compliance only after experiencing an actual breach.With the increasing availability and utility of IT network traffic analysis tools and active user behaviourprobes (e.g., fake-phishing), employees can be given direct and individual feedback to increase theircyber-security awareness and improve their cyber-security practices. Beyond an organization’semployees, the same holds for a country’s citizens, or a government’s public servants. At their best,these user behaviour monitoring tools can be used in an open and transparent way to increaseawareness of individual vulnerability before actual incidents occur.In addition to presenting results from the application of user behaviour monitoring tools to cybersecurity, this paper examines the efficacy of the privacy protection safeguards that they incorporate.These results are applied to public sector approaches to: (a) public awareness of citizen cyber-health;(b) securing online pubic services; and (c) public servant awareness of their own vulnerability to cyberthreats.
// Source
Authors: Chakraborty Soumen